njtech records
11 published records for vendor njtech.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-352 Cross-Site Request Forgery (CSRF)3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-532 Insertion of Sensitive Information into Log File1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
11 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2018-11670Proof of concept | An issue was discovered in GreenCMS v2.3.0603.njtech · greencms · CWE-352 | High8.8 | — | 2.5% | Jun 1, 2018 |
36Monitor | CVE-2018-11671Proof of concept | An issue was discovered in GreenCMS v2.3.0603.njtech · greencms · CWE-352 | High8.8 | — | 2.5% | Jun 1, 2018 |
34Monitor | CVE-2018-12604Proof of concept | GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.njtech · greencms · CWE-532 | High7.5 | — | 13.2% | Jun 20, 2018 |
32Monitor | CVE-2022-28918No exploit | GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plugnjtech · greencms | High8.1 | — | 1.1% | Apr 26, 2022 |
32Monitor | CVE-2020-21366No exploit | Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.njtech · greencms · CWE-352 | High8.0 | — | 0.3% | Jun 20, 2023 |
28Monitor | CVE-2019-25574No exploit | Green CMS 2.x Path Traversal Arbitrary File Downloadnjtech · greencms · CWE-22 | High7.1 | — | 1.1% | Mar 21, 2026 |
28Monitor | CVE-2019-25573No exploit | Green CMS 2.x SQL Injection via cat Parameternjtech · greencms · CWE-89 | High7.1 | — | 0.3% | Mar 21, 2026 |
21Monitor | CVE-2024-22570No exploit | A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arbnjtech · greencms · CWE-79 | Medium5.4 | — | 0.3% | Jan 29, 2024 |
8Monitor | CVE-2025-15187No exploit | GreenCMS File DataController.class.php path traversalnjtech · greencms · CWE-22 | Low2.0 | — | 0.7% | Dec 29, 2025 |
8Monitor | CVE-2025-9415No exploit | GreenCMS index.php unrestricted uploadnjtech · greencms · CWE-284 | Low2.1 | — | 0.4% | Aug 25, 2025 |
7Monitor | CVE-2025-14244No exploit | GreenCMS Menu Management CustomController.class.php cross site scriptingnjtech · greencms · CWE-79 | Low1.9 | — | 0.3% | Dec 8, 2025 |
- CVE-2018-1167036Monitor
An issue was discovered in GreenCMS v2.3.0603.
HighCVSS 8.8Proof of conceptEPSS 2%njtech · greencmsJun 1, 2018
- CVE-2018-1167136Monitor
An issue was discovered in GreenCMS v2.3.0603.
HighCVSS 8.8Proof of conceptEPSS 2%njtech · greencmsJun 1, 2018
- CVE-2018-1260434Monitor
GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.
HighCVSS 7.5Proof of conceptEPSS 13%njtech · greencmsJun 20, 2018
- CVE-2022-2891832Monitor
GreenCMS v2.3.0603 was discovered to contain an arbitrary file deletion vulnerability via /index.php?m=admin&c=custom&a=plugindelhandle&plug
HighCVSS 8.1No exploitEPSS 1%njtech · greencmsApr 26, 2022
- CVE-2020-2136632Monitor
Cross Site Request Forgery vulnerability in GreenCMS v.2.3 allows an attacker to gain privileges via the adduser function of index.php.
HighCVSS 8.0No exploitEPSS 0%njtech · greencmsJun 20, 2023
- CVE-2019-2557428Monitor
Green CMS 2.x Path Traversal Arbitrary File Download
HighCVSS 7.1No exploitEPSS 1%njtech · greencmsMar 21, 2026
- CVE-2019-2557328Monitor
Green CMS 2.x SQL Injection via cat Parameter
HighCVSS 7.1No exploitEPSS 0%njtech · greencmsMar 21, 2026
- CVE-2024-2257021Monitor
A stored cross-site scripting (XSS) vulnerability in /install.php?m=install&c=index&a=step3 of GreenCMS v2.3 allows attackers to execute arb
MediumCVSS 5.4No exploitEPSS 0%njtech · greencmsJan 29, 2024
- CVE-2025-151878Monitor
GreenCMS File DataController.class.php path traversal
LowCVSS 2.0No exploitEPSS 1%njtech · greencmsDec 29, 2025
- CVE-2025-94158Monitor
GreenCMS index.php unrestricted upload
LowCVSS 2.1No exploitEPSS 0%njtech · greencmsAug 25, 2025
- CVE-2025-142447Monitor
GreenCMS Menu Management CustomController.class.php cross site scripting
LowCVSS 1.9No exploitEPSS 0%njtech · greencmsDec 8, 2025